Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer is designing a network architecture for a web application that must be highly available and secure. The application uses an Application Load Balancer (ALB) in front of EC2 instances. Which architecture meets these requirements?

⚠ Common exam trap

A common mix-up: candidates assume both components must be in the same subnet type for simplicity, but the correct design intentionally separates public-facing and private resources to enforce security boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the ALB in public subnets and EC2 instances in private subnets across two Availability Zones.

The correct architecture places the ALB in public subnets so it can receive internet traffic, while EC2 instances reside in private subnets for enhanced security. The ALB acts as a reverse proxy, terminating client connections and forwarding requests to the instances over private IPs, which prevents direct internet access to the instances. Deploying across two Availability Zones ensures high availability by surviving an AZ failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place both the ALB and EC2 instances in private subnets across two Availability Zones.

    Why it's wrong here

    Placing both the ALB and EC2 instances in private subnets means the internet-facing ALB has no public IP address and no route to the internet gateway, so it cannot accept any inbound internet requests. Internet traffic destined for the application never reaches the ALB, making the entire architecture unreachable from the internet. This design only works for internal-only applications, not the internet-facing use case described.

  • ✗

    Place the ALB in private subnets and EC2 instances in public subnets across two Availability Zones.

    Why it's wrong here

    This reverses the required network roles: an ALB placed in a private subnet cannot receive inbound connections from the internet because it has no public IP and no internet gateway route, so the load balancer is unreachable. Meanwhile, the EC2 instances in public subnets are directly reachable from the internet via their public IPs, completely bypassing the ALB and exposing application ports. The correct pattern is the opposite—ALB fronted in public subnets, instances isolated in private subnets.

  • ✓

    Place the ALB in public subnets and EC2 instances in private subnets across two Availability Zones.

    Why this is correct

    This is the correct architecture: the internet-facing ALB resides in public subnets, where it has public IP addresses and a route through the internet gateway to accept client traffic, while the EC2 instances are placed in private subnets with no public IPs or direct internet ingress. The ALB terminates HTTP/HTTPS traffic and forwards requests to instances over private IP addresses using target groups; security groups on the instances should only allow traffic from the ALB security group. This design keeps instances isolated from direct internet access while still providing high availability across two Availability Zones.

  • ✗

    Place both the ALB and EC2 instances in public subnets across two Availability Zones.

    Why it's wrong here

    Although the ALB in public subnets can successfully receive internet traffic, placing the EC2 instances in public subnets gives each instance a public IP address and a direct route to the internet gateway, making them directly reachable from the internet. This bypasses all the protection offered by the ALB and exposes instance-level ports to any internet source, violating the security requirement. A defense-in-depth boundary is lost because instances should be in private subnets with only the ALB having internet exposure.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.